<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>UNC7005 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/actors/unc7005/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 20 Aug 2026 20:18:11 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/actors/unc7005/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Russian Threat Clusters UNC6293, UNC7005, and UNC5976 Targeted OAuth and Device Code Phishing Campaigns</title><link>https://feed.craftedsignal.io/briefs/2026-08-russian-oauth-phishing/</link><pubDate>Thu, 20 Aug 2026 20:18:11 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-russian-oauth-phishing/</guid><description>Three suspected Russian threat clusters are actively conducting targeted phishing campaigns using OAuth abuse, device code manipulation, and AitM attacks via compromised Wi-Fi gateways to hijack credentials and deploy infostealers.</description><content:encoded><![CDATA[<p>Three distinct threat clusters - UNC6293, UNC7005, and UNC5976 - attributed to Russian cyber espionage interests are conducting highly targeted, adaptive phishing campaigns. These clusters focus on personnel within academia, aerospace, defense, government, and think tanks in the U.S. and Europe. The groups employ a variety of sophisticated techniques, including OAuth token theft, device code phishing against Microsoft Entra ID, and WhatsApp account linking abuse. Recent operations, such as those coordinated with the 'CaptiveCrunch' campaign, involve compromising Wi-Fi gateways to facilitate adversary-in-the-middle (AitM) attacks. Once access is gained, these actors leverage commodity infostealers like Vidar, Atomic (AMOS), and custom tooling such as the CornFlake RAT and the ChocoShell PowerShell infostealer to exfiltrate session tokens, browser data, and keystrokes. The use of lures often includes diplomatic invitations, conference registration, and file-sharing themes to induce user interaction.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Initial contact via spearphishing emails containing malicious links or redirection through compromised captive Wi-Fi portals (CaptiveCrunch).</li>
<li>User interacts with fake login pages (OAuth/Device Code phishing) that mimic legitimate services like Google, Microsoft, or WhatsApp.</li>
<li>Victim performs legitimate authentication, which the attacker intercepts to capture session tokens or verification codes.</li>
<li>Attacker-controlled infrastructure (often hosted on illegitimate Google Cloud projects) processes the intercepted tokens.</li>
<li>Deployment of initial-stage payloads, such as the HEADRUSH Excel plugin, HTA files, or &quot;summit companion&quot; applications.</li>
<li>Execution of infostealers (Vidar, Atomic) or modular RATs (CornFlake, ChocoShell) to enumerate the environment and steal session cookies/SSO tokens.</li>
<li>Exfiltration of sensitive data, surveillance recordings, and credentials to a centralized C2 panel branded as 'FruitStone'.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful compromises result in unauthorized account access, theft of session tokens, and long-term espionage through the collection of keystrokes, screenshots, audio, and video recordings. Targets include high-value personnel in the defense industrial base and government sectors. The use of AitM techniques on public Wi-Fi gateways potentially impacts large numbers of users, though the targeted nature of the secondary phishing attempts suggests a focus on specific individuals of interest.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Implement FIDO2/WebAuthn-based phishing-resistant MFA for all Google and Microsoft Entra ID services to mitigate OAuth and device code phishing.</li>
<li>Enforce conditional access policies that restrict logins from suspicious cloud-hosted projects or unrecognized network locations.</li>
<li>Monitor for the use of suspicious Excel plugins and the execution of HTA files or PowerShell scripts associated with the 'ClickFix' lure technique.</li>
<li>Advise users to exercise extreme caution when joining public Wi-Fi networks and to use organizational VPNs that enforce traffic inspection.</li>
<li>Review endpoint logs for the execution of ChocoShell or CornFlake RAT activity patterns on Windows and macOS workstations.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>phishing</category><category>espionage</category><category>oauth-abuse</category><category>aitm</category><category>credential-theft</category></item></channel></rss>